Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

180 advisories

Loading
HTTPX2: Quadratic SSE line buffering can cause CPU denial of service Moderate
CVE-2026-84378 was published for httpx2 (pip) Sep 8, 2026
GalaxySnail Credited to GalaxySnail
Netty: Fragmented ClientHello records trigger quadratic pre-handshake reassembly in default SNI parsing Moderate
CVE-2026-75596 was published for io.netty:netty-handler (Maven) Sep 8, 2026
mauriceng98 Credited to mauriceng98
pypdf: Inefficient handling of non-whitespace inputs in read_until_whitespace Moderate
CVE-2026-82398 was published for pypdf (pip) Sep 2, 2026
arpitjain099 Credited to arpitjain099
NLTK: Quadratic-time DoS in PorterStemmer via long runs of 'y' Moderate
CVE-2026-81722 was published for nltk (pip) Sep 2, 2026
NLTK: Quadratic CPU Exhaustion in `XMLCorpusView._read_xml_fragment()` Moderate
CVE-2026-81723 was published for nltk (pip) Sep 2, 2026
ibfavas Credited to ibfavas
sqlparse: Reindentation of tuple lists causes near-cap quadratic CPU consumption Moderate
CVE-2026-84305 was published for sqlparse (pip) Sep 1, 2026
7thParkk Credited to 7thParkk
league/commonmark: Denial of service via distinctly-named attributes in the Attributes extension High
GHSA-8rr7-cvq3-gmfh was published for league/commonmark (Composer) Sep 1, 2026
manus-use Credited to manus-use
league/commonmark: Denial of service in the SmartPunct and Attributes extensions High
GHSA-jjv6-8j6v-6j52 was published for league/commonmark (Composer) Sep 1, 2026
colinodell Credited to colinodell
league/commonmark: Denial of service via crafted code fences, reference links, and emphasis delimiters High
GHSA-j8pm-gj4c-rq4x was published for league/commonmark (Composer) Sep 1, 2026
colinodell Credited to colinodell
decode-uri-component: Denial of service via exponential decoding of malformed percent-encoded input Moderate
CVE-2026-45822 was published for decode-uri-component (npm) Aug 31, 2026
bnbdr Credited to bnbdr
Duplicate Advisory: Quadratic-time DoS in PorterStemmer via long runs of 'y' High
GHSA-8x48-8g7j-rqxp was published for nltk (pip) Aug 27, 2026 • withdrawn
icalendar has Algorithmic Complexity in Equality High
CVE-2026-55099 was published for icalendar (pip) Aug 25, 2026
tidusec Credited to tidusec
ProTip! Advisories are also available from the GraphQL API